IBM Engineering Lifecycle Management 7.0.3-7.2.0 DOORS XML Exp. DoS
CVE-2026-14979 Published on July 17, 2026

IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOORS could allow a remote attacker to cause a denial of service due to improper handling of XML entity expansion.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-14979 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
LOW

Weakness Type

What is a XEE Vulnerability?

The software uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities. If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.

CVE-2026-14979 has been classified to as a XEE vulnerability or weakness.


Products Associated with CVE-2026-14979

Want to know whenever a new CVE is published for IBM Engineering Lifecycle Management? stack.watch will email you.

 

Affected Versions

IBM Engineering Lifecycle Management: